Platform module
An asset inventory that stays current
You cannot protect what you have not listed, and every framework starts by asking for the list. Certifyi builds the inventory from your cloud, identity and endpoint integrations, assigns owners and classifications, and keeps it current without a spreadsheet.
What an asset inventory is for. ISO 27001 (A.5.9), SOC 2 (CC6.1), CMMC (NIST SP 800-171 3.4) and Cyber Essentials all require an inventory of the systems, devices, software and data in scope, with an owner for each. It is the boundary of your audit and the basis for risk assessment, patching, access reviews and incident response.
What it does
Discover
Automatic discovery
Cloud resources, SaaS applications, endpoints and repositories pulled from AWS, Azure, Google Cloud, Okta, endpoint protection and code hosting integrations.
Classify
Classification and ownership
Every asset gets an owner, a classification (public, internal, confidential, restricted) and the data types it holds.
Scope
Scope boundary
Assets tagged in or out of scope per framework, so the auditor sees exactly what is being assessed and the CUI or PHI boundary is explicit.
Link
Linked controls and risks
Each asset shows the controls that protect it and the risks it carries, so a new asset immediately reveals uncovered controls.
Lifecycle
Lifecycle records
Procurement, change, patch status and decommissioning recorded, with secure disposal evidence for hardware and data.
Dashboard
Asset dashboard
Coverage by control, unowned assets, unclassified data stores and out-of-support software, ranked by what they protect.
How it works
The same record your auditor, your vendors and your team already use.
Step 1
Connect
Integrations import assets in week two; nothing is typed in by hand.
Step 2
Assign
Owners and classifications set by the people who run each system.
Step 3
Scope
In-scope assets per framework define the audit boundary.
Step 4
Maintain
New assets appear automatically and flag missing owners or controls.
Questions about this module
Does the inventory replace our CMDB?
For compliance purposes, yes. If you run a CMDB or MDM already, Certifyi reads from it through integration rather than duplicating it.
What about laptops and phones?
Endpoint protection and MDM integrations list devices with encryption, patch and protection status, which is exactly what Cyber Essentials and SOC 2 endpoint controls require.
How does this help with CMMC?
CMMC assessment starts with the CUI boundary. The inventory tags every asset that stores, processes or transmits CUI, which becomes the System Security Plan scope.
See it on your own scope
Twenty minutes with a compliance lead. Bring your stack; we will show the module against your controls.